Skip to main content
HeboraHeboraGDE 016
  • FRFrançais
  • ENEnglish
  • NLNederlands
Home›SEO & GEO in Belgium›AI Act · chatbot & data
AI Act · chatbot & data

AI chatbot on a Belgian website: what must you disclose and check since 2 August 2026?

A useful chatbot can also collect free-form and sometimes sensitive stories. Since 2 August 2026, the AI Act adds transparency duties; the GDPR still applies to the data actually processed.

Written and checked by Hebora on 15 August 2026.

Business owner and adviser testing AI chatbot transparency on a laptop and phone in Brussels
Field checkThe right test starts before the first message: assistant identity, data sent, retention, deletion and human support.

Short answer

Users must know they are talking to AI at the first interaction

Article 50 of the AI Act requires providers to design direct-interaction systems so people are informed that they are interacting with AI, unless that is obvious. The website owner must also check its own duties as deployer and data controller.

2 August 2026Article 50 transparency obligations apply.
First interactionInformation must be clear and accessible no later than the first interaction.
€15m / 3%AI Act ceiling for certain operator breaches; lower SME rule and case-by-case decision.
Free textA message may unexpectedly contain health, financial, identity or other personal data.

When and how to disclose an AI chatbot

The information must be clear, visible and accessible no later than the first interaction. A label such as “AI assistant” in the chat header and a short sentence before the input are stronger than a disclosure buried in general terms.

The duty concerns direct interaction with an AI system. It is not a general rule requiring every website built with AI to carry a label. Synthetic content, deepfakes and certain public-interest text follow other paragraphs and exceptions in Article 50.

The GDPR still applies behind the chat window

The Belgian DPA notes that free text makes it hard to predict all data people may send. Limit what is requested, warn against unnecessary sensitive information, define purposes, recipients and retention, and provide access and deletion paths.

  • Before input: AI identity, message use, useful warning and link to detailed information.
  • During: data minimisation, detection of obvious secrets, human escalation and no misleading promises.
  • After: documented retention, rights, deletion, logs and supplier control.

The AI Act ceiling is not a small website’s invoice

Article 99 provides up to €15 million or 3% of worldwide annual turnover for certain breaches of operator duties, including Article 50. For SMEs and start-ups, the applicable maximum is the lower of those amounts. Nature, severity, duration, responsibility, cooperation and corrective action are assessed.

The figure matters only when the system, role and obligation are actually in scope. Presenting it as an automatic fine for every chatbot would be false.

What Hebora tests on the published chatbot

  1. First interaction. AI label, placement, readability, accessibility and mobile consistency.
  2. Flows. Messages, files, metadata, suppliers, region, logs and exposed keys.
  3. Risk journeys. Sensitive data, deletion request, hallucination, incident and human handover.
  4. Delivery. Captures, flow inventory, configured retention, technical corrections and questions for the DPO or lawyer.
Clear boundary

Hebora performs technical audits and corrections. This content is not legal advice, does not certify compliance and does not replace a lawyer or DPO when your situation needs legal interpretation.

Verified official sources

  • EUR-Lex — European Artificial Intelligence Act, Articles 50 and 99
  • EUR-Lex — Regulation (EU) 2026/1744, Digital Omnibus on AI
  • European Commission — guidelines on AI Act transparency obligations
  • FPS Economy — you use AI in your company
  • Belgian Data Protection Authority — chatbots, innovation and data protection (official source in Dutch)
  • EUR-Lex — General Data Protection Regulation (GDPR)

Sources checked on 15 August 2026.

Technical audit

Check my chatbot before launch

Hebora tests first-contact disclosure, data sent, retention, deletion and human escalation, then delivers the evidence.

Audit my chatbot

Continue the review

AI-built website: what still needs checking in Belgium

The website owner must still check business disclosures, legal grounds, notices to individuals, cookies, security, supplier contracts and — when applicable — e-commerce and accessibility rules. The platform helps build; it does not make those decisions for you.

Lovable Cloud and GDPR: who is responsible for what in Belgium?

Lovable’s DPA generally describes the customer as controller and Lovable as processor for data handled on the customer’s behalf. The customer still configures the app, informs users, chooses data and integrations, and handles requests to exercise data rights.

Cookie banner in Belgium: what must be blocked before consent

The Belgian Data Protection Authority requires prior consent for cookies that are not strictly necessary, a genuine choice, refusal as accessible as acceptance and easy withdrawal. Necessary cookies may operate without consent, but they must genuinely be necessary.

HeboraHebora
Catalogue
Hebora, Belgium
Entry
GDE 016
Edition
2026
  • HEB 04Websites
  • HEB 05Visibility
  • HEB 06Automation
  • HEB 07AI Assistant

Index

Services for small businessesHebora projectsConstruction and homeClient referencesWebsite assessmentContact HeboraAbout HeboraBusiness introducerHebora guides
Legal noticePrivacy policy© 2026 Hebora
  • Home
  • Work
  • Services
  • Contact
  • 0My offer
  • Legal
AssessmentThe audit of your siteBusiness introducerYou introduce, we buildGuidesPractical guides, nothing soldClient reviewsWhat our clients say about us
HeboraHeboraPRIV / 01

YOUR CHOICE

Cookies, no detours.

No advertising cookies. Your language and favourite projects stay on this device.

OPTIONS

What this device remembers.

Privacy policy